About RSS
Search for: in 

Windows Watch - an XP & Vista blog

shopping
Is Marks and Spencer's in hot water?
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Information Commissioner’s Office to investigate Marks and Spencer’s security procedures

Details of 26,000 M & S employees could be at risk

Andrea-Marie Vassou, Computeract!ve 11 May 2007
ADVERTISEMENT

The Information Commissioner’s Office (ICO) has said it will be investigating Marks and Spencer’s security procedures after the company admitted losing a notebook containing the information of 26,000 employees.

The notebook contained salary details, addresses, dates of birth, national insurance and phone numbers. It was taken from a printing firm, which had been given the personal information in order to write to Marks and Spencer employees about pension changes.

In a statement the ICO said, that it would " expect a full explanation from Marks and Spencer to establish what and how this has happened."

"We will want to ensure that the company has robust procedures in place and that these are followed to protect personal information in future.

"The Information Commissioner's Office takes security breaches very seriously [and]
organisations which process personal information must ensure it is held securely. 

"This is an important Principle of the Data Protection Act,” it added.

However, Marks and Spencer’s could find itself in hot water after a representative for the company confirmed that the notebook was only “password protected.”

“The notebook had no encryption in place,” she told Computeractive.

This, according to Tony Jackson business development manager for Data Company Vigil software would not be enough to ensure the safety of information,

“Potentially if there is an encryption programme, in place that uses many algorithms as well as two factor authentications then the information installed in the notebook will be more or less secure," he told Computeractive.

“If this is not the case then information will easily be accessible, as getting through a password is not difficult.” he added.

In light of the incident which happened three weeks ago, Marks and Spencer’s has said it will review its security policies but could “not confirm” what these would be or entail. 

The retailer has also given employees affected by the breach unlimited credit checks and set up a number of helplines and email contacts to advise them.

The Marks and Spencer's incident follows a number of incidents over the past year. Late last year the Metropolitan police admitted to losing three notebooks carrying personal information about employees and only last week the NHS admitted a laptop containing the names, addresses and bank details of some 10,000 employees had been stolen from a building in Truro, Cornwall.

This week the Information Commissioner also called for stronger power to enable his office to carry out inspections and audits of organisations without consent to ensure effective compliance with the Data Protection Act.

See also:

picture of a laptopHospital trust says no patient records have been stolen  08 May 2007
Public expects to be notified immediately of data breaches  18 Apr 2007

All Online
Tags: Marks and Spencer, Information Commissioner’s Office

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | City of London
ICT Support Officer £27,320 - £33,370 pa inc. depending on experience (pay award pending) Maternity cover for up to one year Guildhall, London EC2 Bring your IT experience to one of the country's most prestigious ... more >
London, United Kingdom | The Crown Estate
 EDM Administrator - London - £22,300 to £24,200pa The Crown Estate is a unique organisation that manages a vast and varied property portfolio, comprising commercial, agricultural and marine interests throughout Britain. We are looking for an ... more >
Berkshire, Berkshire, United Kingdom | EDS
EDS are currently looking to recruit an experienced Core Infrastructure Project Manager to join our Project Management Defence team in one of the following locations: Reading or Bracknell (Berkshire) or Camberley (Surrey). Summary: Within DII ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT